Absolutely. There's several ways to do this. Lets assume your field is called 'foo'.
The most straightforward way is to use the
Using stats opens up the door to collect other statistics by those unique values. For example:
which will take the average of a field called
Another way worth mentioning is to just use
answered 12 May '10, 20:08
Actually, we were hoping that, because it is an indexed field, there is some kind of metadata or list that is persisted that we could access quickly, without running a search over all our events. I guess the simplest case would be source, sourcetype, or host - is there any quick way to find the list of all indexed hosts without going through stats or some other search? It seems like there must be, because the summary view displays those. We'd like to pull that type of summary information for any indexed field to get a list of all possible field values.
answered 13 May '10, 16:23